Lurking beneath Comet AI's sleek browser interface is a minefield of security vulnerabilities that should make users think twice. This AI-powered browser has a dirty little secret: it can't tell the difference between your commands and hidden malicious instructions embedded in web pages. Pretty basic stuff for a so-called "intelligent" assistant, right?
The problem is serious. Comet falls for indirect prompt injection attacks where hackers hide commands in web content. Your AI helper sees these instructions and thinks, "Must obey!" No questions asked. Brave browser already flagged these issues to Perplexity, but full fixes? Still waiting. Unlike traditional bots, AI learns and adapts, making these security flaws even more concerning as the system continues to process user interactions.
Here's where it gets scary. Imagine fake CAPTCHAs that trigger Comet to enter your personal data automatically. Or the "PromptFix" exploit that tricks the AI into adding items to shopping carts and entering your private information. These attacks demonstrate how single points of failure emerge when human intuition is removed from security evaluations. These exploits were thoroughly demonstrated by Guardio Labs who showed how vulnerable the browser truly is. The browser might even complete purchases using your saved payment details. All while you're blissfully unaware.
Security nightmares lurk behind Comet's sleek facade, with AI eagerly obeying hidden commands while your data and wallet remain vulnerable.
Phishing attacks become supercharged with Comet. Traditional scams rely on human error, but Comet removes that skepticism entirely. It navigates to malicious sites, interacts with them, and might hand over your credentials without hesitation. Your AI assistant just became a hacker's best friend.
The security guardrails? Nearly non-existent. There's a fundamental breakdown in the "trust chain" with these agentic browsers. They believe whatever they read, lacking the verification mechanisms found in traditional browsers. It's like hiring a secretary who opens every piece of mail marked "urgent" and follows all instructions inside—even the ones from obvious scammers.
Data privacy concerns abound too. Comet could transmit sensitive information to third parties without proper notification. The transparency about what sites it visits and what data it collects remains murky at best.
The convenience of AI browsing comes at a steep price. Your security. Your privacy. Your data. Is having an AI assistant really worth handing hackers the keys to your digital life?

